Part 10 · 1 chapters · ~8 min

tcpdump and Wireshark

Capturing packets safely, capture and display filters, reading a TCP conversation, following streams, spotting retransmissions, resets and zero windows, decrypting TLS in a lab with key logs, and analysing DNS and HTTP in captures.

20

Capture and read

code
# capture: filter at capture time to keep files small; -s 0 for full packets
tcpdump -i any -nn -s 0 -w /tmp/api.pcap 'host 203.0.113.10 and port 443'
tcpdump -i any -nn 'udp port 53'                      # watch DNS live
tcpdump -i any -nn 'tcp[tcpflags] & (tcp-syn|tcp-rst) != 0'   # connection attempts and resets

# Wireshark display filters
tcp.analysis.retransmission        tcp.flags.reset == 1        tcp.analysis.zero_window
dns.flags.rcode != 0               http.response.code >= 500    tls.handshake.type == 1

# lab only: decrypt TLS by having the client log its session keys
SSLKEYLOGFILE=/tmp/keys.log curl https://localhost:8443/
# Wireshark → Preferences → TLS → (Pre)-Master-Secret log filename = /tmp/keys.log
Wireshark featureuse
Follow TCP Streamsee one conversation as text
Statistics → Conversationswho talked to whom, how much
Expert Informationretransmits, resets, malformed packets, summarised
I/O graphsthroughput and retransmits over time
TCP stream graph (Stevens)sequence numbers over time: stalls and window limits are visible

Safety: captures can contain personal data and credentials; capture the minimum, store briefly, and never key-log production TLS.